I. Introduction
1. Purpose of CI Protection
I.
Introduction
National life and socioeconomic activities fully depend on diverse social infrastructures, and
information systems are being broadly utilized to enable infrastructures to properly fulfill their functions.
Under such circumstances, there is a need for the public and private sectors to make all-out efforts to
intensively protect critical infrastructure services (CISs), such as information and communication
services, electric power supply services and financial services, whose suspension or deterioration is
highly likely to have tremendous impact. The private sector should not completely count on the
government, nor should the government leave everything to the private sector. Close public-private
collaboration is indispensable. Therefore, the government established the Cybersecurity Policy for
Critical Infrastructures Protection (the “Cybersecurity Policy”), a shared policy between the government,
which bears responsibility for promoting independent measures by CI operators relating to CI
cybersecurity and implementing other necessary measures, and CI operators, which independently carry
out relevant protective measures, as a basic framework for CI protection, and has promoted this initiative
to date.
Threats surrounding CI are becoming increasingly advanced and sophisticated year by year. On the
other hand, due to differences in how systems are used in each CI field, the threats faced by each
organization are becoming increasingly distinctive. In view of this situation, the government has based
this Cybersecurity Policy for Critical Infrastructure Protection (“this Cybersecurity Policy”) on the
Fourth Edition of the “Cybersecurity Policy for Critical Infrastructure Protection” (the “Fourth Policy”),
which serves as a reference for critical infrastructure protection, while also actively updating the policy
to further enhance critical infrastructure protection based on public-private collaboration. This will
enable critical infrastructure fields as a whole to flexibly respond to trends in future threats and changes
in the environment surrounding systems and assets.
1.
Purpose of CI Protection
1
Based on the concept of mission assurance, the purpose of CI protection (CIP) is to maintain safe
and continuous provision of CISs. Taking the view that natural disasters, mismanagement, cyberattacks,
and changes in the environment surrounding CI constitute risks that make the continuous provision of
CISs uncertain, the aim is to ensure resilience and prevent serious impact on national life and
socioeconomic activities, from the dual aspects of limiting risk to acceptable levels, and in terms of
preparing for CISs outages, taking appropriate action in the event of outages, and ensuring rapid
restoration of services.
1
In the Cybersecurity Strategy (Cabinet Decision of September 28, 2021), the concept of mission assurance is described as follows: “Refers to
the condition in which any organization represented by companies, CI operators (excl. related entities), and government bodies understand the
operations or services that they should carry out as their missions, and ensure necessary capabilities and resources to reliably execute such
missions. This means that senior executives or managers of each organization should identify operations or services that represent their missions
and take all responsibility for secure and sustainable provision, rather than making cybersecurity initiatives themselves the goal.”
1